Reference

Your Rights and Our Policy Commitments

kvttoto operates under a framework designed to be clear about how your account, your data, and your wallet activity are handled. Access and eligibility depend on local law and are available only where permitted in your region — including supported areas across Indonesia.

Account data rightsDANA, OVO, GoPay wallet policyCookie and session termsData retention rulesContact and request paths
kvttoto Your Rights and Our Policy Commitments
HOW WE HANDLE IT

Data Handling, Security and Your Account

We have structured our data practices around the principle that you should control what we hold on your account. Wallet data from DANA, OVO and GoPay is scoped tightly — we retain only what the transaction requires, and payment credentials are never stored on our servers. Your account password is hashed; session tokens expire after a period of inactivity. Here is how we approach each key area.

Data Minimisation

We collect only what is necessary for account operation and payment processing. Wallet identifiers from DANA, OVO and GoPay are used solely to match your deposit or withdrawal to your account.

Cookie Controls

Session cookies keep your lobby state intact across page loads on mobile. You can clear cookies at any time through your browser settings; doing so will log you out of the current session.

Account Security Steps

Login uses OTP verification sent to your registered number. If you notice unfamiliar account activity, contact support immediately and we will lock the account pending a security review.

Retention and Deletion

Active account data is retained while your account is open. Once closed, we apply a defined retention window before deletion, unless a regulatory hold applies. You can request deletion at any time.

POLICY CONTACT

How to Reach Us on Legal Matters

If you have a question about your rights, need to request your stored data, or want to flag a policy concern, our support team handles these through dedicated channels. We aim to acknowledge legal data requests within a reasonable period and respond in full once verification is complete.

Team online

Live Chat

Open the chat widget from any page on the platform. Identify your request as a legal or data query and our team will route it to the right handler.

Email Support

Send your data request or policy question to our support address. Include your registered phone number or wallet identifier so we can verify your account quickly.

Account Settings Path

Log in, go to Account Settings, then select Privacy and Data. From there you can submit a data access or deletion request directly without contacting support.

Legal and Policy Questions Answered

These are the questions we hear most often about how our legal terms apply to your account and your data. Each answer reflects our actual policy, not a generic statement.

No. We store only the transaction reference and account identifier needed to match your transfer to your account. Full wallet credentials are never stored on our servers.

Log in and go to Account Settings, then Privacy and Data, and submit a data access request. You can also send the request via live chat or email with your registered phone number for verification.

After account closure, we apply a structured retention window before permanently deleting your data. If a legal or regulatory hold applies, we will inform you of the extended period.

Transaction data processed via GoPay is used only to complete your deposit or withdrawal. We do not sell or share payment data with third parties outside of what the payment rail itself requires.

Yes. Contact support via live chat or email, or use the Account Settings path. We will verify your identity and update the inaccurate information within a reasonable timeframe.

Access and eligibility depend on local law and the region you are in. Our service is available only where local law permits. Check the terms applicable to your region before opening an account.
Reference

Legal

Service availability depends on eligible regions and local law. Users should check local rules before opening an account.

Access may be available only where local law permits.